Re: [PATCH v3 10/10] x86/virt/tdx: Verify structure member sizes against metadata field IDs

From: Edgecombe, Rick P

Date: Wed Sep 30 2026 - 20:33:44 EST


On Tue, 2026-09-29 at 22:38 -0700, Chao Gao wrote:
> +/*
> + * Bits 33:32 of a field ID hold the log2 of the metadata field size in
> + * bytes. See "Metadata Field Identifier" in the Intel TDX Module ABI
> + * Specification.
> + */
> +#define TDX_FIELD_SIZE(field_id) (1 << (((field_id) >> 32) & 0x3))
> +

Would it maybe be clearer to just encode the 4 possible cases? I prompted an AI
with "...maybe the 4 cases could just be encoded instead of the masking and bit
shifting" and a bit of followup, and it generated:

#define TDX_FIELD_SIZE_MASK GENMASK_ULL(33, 32)

#define TDX_FIELD_SIZE_CODE(_size) \
((_size) == 1 ? 0 : \
(_size) == 2 ? BIT_ULL(32) : \
(_size) == 4 ? BIT_ULL(33) : \
(_size) == 8 ? TDX_FIELD_SIZE_MASK : \
~0ULL)

#define TDX_FIELD_SIZE_CHECK(_field, _type, _member) \
BUILD_BUG_ON_ZERO(((u64)(_field) & TDX_FIELD_SIZE_MASK) != \
TDX_FIELD_SIZE_CODE(sizeof_field(_type, _member)))

Reverses the format being checked. Looks a bit simpler to me.

I think we could also keep the same type of comparison (size in bytes), but
switch to the explicit 4 case ternary style.

What do you think? I think you see a bit more bit math like that in KVM than you
do in arch/x86.